APT29/Nobelium Cobalt Strike C2 setup with custom certificates and redirections (Pay attention to how similar threat actor communitypowersports[.]com domain is to the genuine sanjosemotosport[.]com).
These domain similarities or sometimes typosquatting SSL domains are techniques used frequently by Threat Actors.
Press enter or click to view image in full size
APT29/Nobelium Cobalt Strike C2 redirector setup
Here you can see how the mode rewrite redirector works.
Press enter or click to view image in full size
Cobalt Strike C2 mode rewrite setup
Initial Access Attack Analysis HTML (EnvyScout) dropper used by Russian APT29/Nobelium in recent…